Repository navigation
Add --authmode to setup all: control agent identity permission grants (OBO/S2S/both) - #391
Merged
Sellakumaran Kanagarathnam (sellakumaran) merged 6 commits intoApr 29, 2026
Conversation
Introduce --authmode (obo|s2s|both) to a365 setup all and related flows, allowing users to control how agent identity permissions are granted. For non-DW agents, inheritable permissions and AllPrincipals grants are always skipped to avoid requiring Global Admin. The orchestrator now applies delegated grants, app role assignments, or both based on authMode, with PowerShell fallback for S2S if needed. The dry-run plan and summary output reflect these changes. Agent365Config and docs updated to support authMode. Includes extensive tests for all authMode values and validation logic. GraphApiService now treats "Permission entry already exists" as success.
- Dry-run no longer detects tenant ID via az CLI when not needed. - "Inheritable Permissions" now shows "skipped (permissions set directly on agent identity)" for non-AI Teammate agents. - Messaging endpoint step output clarified to "skipped (non-M365 agent)". - Improved error message for --authmode with --aiteammate. - Tests updated for new output and error messages. - Changelog updated to reflect these changes.
Sellakumaran Kanagarathnam (sellakumaran)
requested review from
a team
as code owners
April 28, 2026 18:55
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
Contributor
There was a problem hiding this comment.
Pull request overview
Adds an --authmode (obo|s2s|both) option to a365 setup all to control whether non-DW blueprint agents receive permissions via delegated (OBO), app-role (S2S), or both, and updates dry-run/summary output and docs accordingly.
Changes:
- Introduces
--authmodeonsetup alland threads the resolved mode throughSetupContextand the non-DW setup orchestrator. - Updates non-DW dry-run plan + setup summary wording to reflect “permissions set directly on agent identity” and to avoid implying inheritable permissions/admin consent for non-DW flows.
- Makes OAuth2 grant creation more idempotent by treating “Permission entry already exists” as success; updates tests/docs/changelog.
Reviewed changes
Copilot reviewed 12 out of 12 changed files in this pull request and generated 8 comments.
Show a summary per file
| File | Description |
|---|---|
| src/Tests/Microsoft.Agents.A365.DevTools.Cli.Tests/Commands/SetupCommandTests.cs | Adds CLI-level --authmode validation tests. |
| src/Tests/Microsoft.Agents.A365.DevTools.Cli.Tests/Commands/NonDwBlueprintSetupOrchestratorDryRunTests.cs | Updates and adds dry-run assertions for authMode behavior. |
| src/Microsoft.Agents.A365.DevTools.Cli/design.md | Documents authMode as a persisted config field. |
| src/Microsoft.Agents.A365.DevTools.Cli/Services/GraphApiService.cs | Treats “Permission entry already exists” as idempotent success for oauth2 grants. |
| src/Microsoft.Agents.A365.DevTools.Cli/Models/README.md | Documents AuthMode on Agent365Config. |
| src/Microsoft.Agents.A365.DevTools.Cli/Models/Agent365Config.cs | Adds AuthMode property and carries it through cloning helpers. |
| src/Microsoft.Agents.A365.DevTools.Cli/Commands/SetupSubcommands/SetupHelpers.cs | Adjusts setup summary logic and messaging endpoint “skipped” text. |
| src/Microsoft.Agents.A365.DevTools.Cli/Commands/SetupSubcommands/SetupContext.cs | Adds AuthMode + helper booleans for gating OBO/S2S steps. |
| src/Microsoft.Agents.A365.DevTools.Cli/Commands/SetupSubcommands/README.md | Adds authMode documentation (currently overstates command availability). |
| src/Microsoft.Agents.A365.DevTools.Cli/Commands/SetupSubcommands/NonDwBlueprintSetupOrchestrator.cs | Reworks non-DW plan/execution to skip Phase 2a/2b and apply grants to agent identity per authMode (with PS fallback for S2S). |
| src/Microsoft.Agents.A365.DevTools.Cli/Commands/SetupSubcommands/AllSubcommand.cs | Adds --authmode option, validation, and wiring into dry-run and execution context. |
| CHANGELOG.md | Adds release notes for --authmode and related dry-run/summary fixes. |
- Enforces allowed values for authMode in config and CLI, with normalization to prevent silent misconfigurations. - Adds admin prompt for missing CLI app: Global Admins can create and consent or enter an existing ID; non-admins prompted for ID only. - Implements CreateCliClientAppAsync for app/SP creation and admin consent grant, with isFallbackPublicClient and WAM redirect URI set at creation time. - Reverts WellKnownClientAppDisplayName to "Agent 365 CLI" (was left as personal test value "Agent 365 CLISellak"). - Prevents duplicate admin action rows in S2S summary output. - Expands test coverage for all new flows; stubs GraphPatchAsync to eliminate real subprocess call in CreateCliClientAppAsync test.
Copilot started reviewing on behalf of
Sellakumaran Kanagarathnam (sellakumaran)
April 28, 2026 20:54
View session
Refactor setup summary to accurately reflect S2S app role assignment and delegated grant status, preventing duplicate or misleading "Action Required" rows. Reorder non-DW agent steps to match dry-run order. Add error logging for failed redirect URI patching after app registration. Add unit tests for S2S app role assignment scenarios. Update changelog to clarify Global Admin flows and summarize these improvements.
ajmfehr
previously approved these changes
Apr 28, 2026
Sellakumaran Kanagarathnam (sellakumaran)
enabled auto-merge (squash)
April 28, 2026 22:06
Sellakumaran Kanagarathnam (sellakumaran)
disabled auto-merge
April 28, 2026 22:19
Sellakumaran Kanagarathnam (sellakumaran)
enabled auto-merge (squash)
April 28, 2026 23:04
- Switch blueprint SP creation to /serviceprincipals/graph.agentIdentityBlueprintPrincipal per MSFT guidance - Revise admin consent instructions: Option A (Entra portal) now covers only delegated permissions; application permissions for agent identity must be granted via PowerShell (Option B) - Remove step 7 from Option A and add note redirecting to PowerShell - Update PowerShell instructions to use agent identity SP object ID and assign app roles only to agent identity in non-DW flows - Add AgentIdentity.Read.All to required permissions and clarify Application.ReadWrite.All is not needed for blueprint creation - Change agent registrations endpoint to /beta/copilot/agentRegistrations - Update unit tests to match new consent flow and permission requirements - Aligns with latest Agent ID team guidance for correct admin consent and permission assignment
Copilot started reviewing on behalf of
Sellakumaran Kanagarathnam (sellakumaran)
April 29, 2026 01:16
View session
- Treat AgenticAppId as the SP object ID directly, removing the need for appId-to-SP lookup in non-DW flows.
- Track and report the effective auth mode ("obo", "s2s", "both") in setup results for more accurate permission grant summaries.
- Enhance PowerShell instructions: add 'Directory.Read.All' scope and optionally display agent identity SP display name.
- Refine summary logic to distinguish between full, partial, and pending permission grants, especially in "both" mode.
- Add EffectiveAuthMode property to SetupResults.
- Update tests to reflect new SP object ID handling and clarify test intent.
- Improves correctness, clarity, and user feedback for S2S and delegated grant scenarios.
ajmfehr
approved these changes
Apr 29, 2026
Pujarini Mohapatra (biswapm)
approved these changes
Apr 29, 2026
Sellakumaran Kanagarathnam (sellakumaran)
merged commit Apr 29, 2026
a8765b2
into
main
9 checks passed
Sellakumaran Kanagarathnam (sellakumaran)
deleted the
users/sellak/setup-authtype
branch
April 29, 2026 03:26
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Introduce
--authmode (obo|s2s|both)toa365 setup all, giving users control over how the agent identity service principal receives permissions:For non-AI Teammate agents, inheritable permissions and AllPrincipals grants (Phase 2a/2b) are always skipped regardless of
authMode.Changes
setup all: new--authmodeoption; validated against--aiteammate(mutually exclusive)NonDwBlueprintSetupOrchestrator: applies delegated grants, app role assignments, or both; S2S PowerShell fallback prints only for specs that actually failedSetupHelpers: dry-run plan and live summary updated to reflect authMode; messaging endpoint messages cleaned upAgent365Config: newauthModeinit-only property — persists across runs when set ina365.config.jsonGraphApiService: treats"Permission entry already exists"as success — grants are idempotent on re-run--authmodecode removed fromsetup blueprintandsetup permissions(no agent identity grant step in those commands)README.md,design.md,Models/README.md,CHANGELOG.mdTest Plan
--authmode obodry-run: step 3 skipped, step 5 shows delegated grants only--authmode s2sdry-run: step 3 skipped, step 5 shows app perms only--authmode bothdry-run: step 5 shows both rows--authmode+--aiteammatereturns exit code 1 with explanatory error--authmodevalue returns exit code 1--authmodedefaults to OBO behavior (delegated grants present, S2S absent)scp: Agent365.Observability.OtelWrite